Red Hat JBoss EAP XP 5.0 Update 2.0 vulnerability

A security issue was discovered in the LRA Coordinator component of Narayana. When Cancel is called in LRA, an execution time of approximately 2 seconds occurs. If Join is called with the same LRA ID within that timeframe, the application may crash or hang indefinitely, leading to a denial of service.

Published 2 Jan 2025Updated 7 Sep 20266 sources
CVSS 5.9

Source timeline

CVE record published by NVDView source ↗